Lucene search

K
nvd[email protected]NVD:CVE-2022-24010
HistoryAug 05, 2022 - 10:15 p.m.

CVE-2022-24010

2022-08-0522:15:09
CWE-120
web.nvd.nist.gov
2
buffer overflow
tcl linkhub
mesh wi-fi
vulnerability
configuration value
cwmpd binary
attacker

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.8%

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cwmpd binary.

Affected configurations

Nvd
Node
tcllinkhub_mesh_wifi_ac1200Matchms1g_00_01.00_14
AND
tcllinkhub_mesh_wifi_ac1200Match-
VendorProductVersionCPE
tcllinkhub_mesh_wifi_ac1200ms1g_00_01.00_14cpe:2.3:o:tcl:linkhub_mesh_wifi_ac1200:ms1g_00_01.00_14:*:*:*:*:*:*:*
tcllinkhub_mesh_wifi_ac1200-cpe:2.3:h:tcl:linkhub_mesh_wifi_ac1200:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.8%

Related for NVD:CVE-2022-24010